ISO/IEC 27002
Definition
A guidance standard (not certifiable) that provides implementation advice for each of the 93 controls in ISO 27001 Annex A. Updated in 2022 to align with the revised control structure. Organisations are certified against 27001; auditors use 27002 as a reference for assessing control implementation.
- Type
- Guidance standard, not certifiable
- Complements
- ISO/IEC 27001 Annex A
- Control count referenced
- 93 controls
- Last major update
- 2022
Common questions
If 27002 cannot be certified against, what is it used for?+
Auditors and implementers use it as a practical reference for how each Annex A control in 27001 might actually be implemented. Organisations get certified against 27001, then cite 27002 guidance to justify their chosen implementation of a given control.
Why did the 2022 update matter for organisations already certified?+
It restructured and reduced the control set to align with the revised 27001 Annex A, so organisations certified under the older control list needed to map their existing controls to the new structure at their next surveillance or recertification audit.
Related terms
- Annex a
- The normative annex to ISO/IEC 27001 that lists 93 information security controls across four themes: organisational (37 controls), people (8), physical (14),...
- High-Level Structure (HLS)
- The common clause framework mandated by ISO for all management system standards. Clauses 4 through 10 of ISO 27001 follow the same...
- Information Security Management System (ISMS)
- The set of policies, processes, procedures, and controls that an organisation establishes to manage information security risk. ISO 27001 specifies the requirements...
- Risk Owner
- The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
- Statement of Applicability (SoA)
- A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification...